Computer Security and Cyber LawUnit 1310 min read
Digital Signatures, Non-Repudiation & Cryptographic Proofs
Unit 13 of Computer Security and Cyber Law covers digital signatures (DSS, RSA), non-repudiation, timestamping, and real-world applications in e-commerce, contracts, and legal evidence, with worked examples from eSewa, NEPSE, and Kathmandu traffic fines.
TAKEAWAYS:
- Digital signatures use asymmetric cryptography (DSS/RSA) to bind identity to data, ensuring authenticity and integrity.
- Non-repudiation prevents a sender from denying they sent a message, using timestamps and third-party validation.
- Timestamping (RFC 3161) adds legally binding time evidence to digital documents.
- Real-world uses include eSewa transactions, NEPSE share trading, and Kathmandu traffic fine receipts.
- Weaknesses like key compromise or timestamping fraud must be mitigated via multi-party validation.
- Legal frameworks (e.g., Nepal’s Electronic Transactions Act 2063) recognize digital signatures as valid evidence.
Core Concepts: What Is a Digital Signature?
A digital signature is a mathematical scheme for verifying the authenticity of digital messages or documents. It combines:
- Asymmetric cryptography (public/private keys)
- Hashing (to ensure data integrity)
- Binding to a specific identity (e.g., a user’s private key).
Unlike handwritten signatures, digital signatures cannot be forged if the private key is secure. They solve three critical problems:
- Authenticity: Prove the signer is who they claim to be.
- Integrity: Ensure the message was not altered.
- Non-repudiation: Prevent the signer from denying they signed.
graph LR
A["Original Message"] -->|"Hashing"| B["Hash Value"]
B -->|"Private Key"| C["Digital Signature"]
C -->|"Public Key"| D["Verification"]
D -->|"Match?"| E["Yes: Authentic\nNo: Tampered"]
Shows the step-by-step flow from message to verification. (Image: Thiagocv, CC BY-SA 4.0, via Wikimedia Commons)
How Digital Signatures Work: DSS vs. RSA
Two dominant standards are used in practice:
| Feature | DSS (Digital Signature Standard) | RSA (Rivest-Shamir-Adleman) |
|---|---|---|
| Algorithm | Based on DSA (Digital Signature Algorithm) | Based on public-key cryptography |
| Key Size | 1024–3072 bits (NIST recommends 2048+ for security) | 1024–4096 bits (2048+ recommended) |
| Speed | Faster signing, slower verification | Slower signing, faster verification |
| Use Case | Government, military (FIPS 186-5 compliant) | E-commerce, SSL/TLS, PGP |
| Hash Function | SHA-256, SHA-384, SHA-512 | MD5, SHA-1, SHA-256 (depends on implementation) |
| Security | Resistant to chosen-message attacks | Vulnerable to factoring attacks (but mitigated with large keys) |
Worked Example: Signing a Kathmandu Traffic Fine Receipt
Scenario: A driver receives a fine via eSewa for speeding on the Ring Road. The fine receipt must be digitally signed to prove:
- The fine was issued by Kathmandu Metropolitan City (KMC).
- The amount and details were not altered.
- The driver cannot claim they didn’t receive it.
Steps:
KMC’s System:
- Generates a hash of the fine details (e.g.,
SHA-256("Fine ID: KMC-2024-001 | Amount: NPR 5000 | Date: 2024-05-15")). - Signs the hash with KMC’s private key (stored securely in a Hardware Security Module).
- Attaches the signature to the receipt.
- Generates a hash of the fine details (e.g.,
Driver’s Verification:
- Uses KMC’s public key (published on KMC’s website) to verify the signature.
- If the hash matches, the receipt is authentic and unaltered.
Real-World Tie-In: KMC’s e-Fine system uses digital signatures to issue fines via SMS/eSewa. Drivers can verify the signature using KMC’s public key to dispute fraudulent claims.
Non-Repudiation: The Legal Glue
Non-repudiation ensures that a party cannot deny an action they committed. For digital signatures, this is achieved via:
- Timestamping: Proves when the signature was applied (critical for disputes).
- Third-Party Validation: A trusted authority (e.g., a Certificate Authority like Nepal Government’s CA) vouches for the signature.
- Audit Trails: Logs of signing events (e.g., in eSewa transactions).
How Timestamping Works (RFC 3161)
A Time Stamping Authority (TSA) adds a cryptographic timestamp to a document:
- The signer sends the document + current time to the TSA.
- The TSA:
- Generates a hash of the document + timestamp.
- Signs the hash with its private key.
- Returns a Time Stamp Token (TST).
- The TST is appended to the document, proving the exact time of signing.
Example: NEPSE (Nepal Stock Exchange) uses timestamping for share trading orders to prevent traders from denying they placed an order.
sequenceDiagram
participant Signer as Trader (NEPSE User)
participant TSA as Time Stamping Authority
participant NEPSE as Nepal Stock Exchange
Signer->>TSA: Request Timestamp (Order: "Buy 100 shares of NMB, Price: NPR 1500")
TSA->>TSA: Hash Order + Current Time (2024-05-20 14:30:00)
TSA->>TSA: Sign Hash with TSA Private Key
TSA->>Signer: Return TST (Time Stamp Token)
Signer->>NEPSE: Submit Order + TST
NEPSE->>NEPSE: Verify TST with TSA Public Key
NEPSE->>Signer: Confirm Order ExecutionReal-World Applications in Nepal
eSewa Payments:
- Idea Used: Digital signatures for transaction authorization.
- How: When you pay a bill via eSewa, the app signs the payment request with your private key (stored in your phone’s secure enclave). The bank verifies the signature before processing.
- Non-Repudiation: If you deny paying, eSewa can present the signed transaction log as evidence.
NEPSE Share Trading:
- Idea Used: Timestamped digital signatures for order execution.
- How: Brokers sign trading orders with their private keys, and NEPSE’s system timestamps them. This prevents brokers from claiming orders were altered or never sent.
Khalti Business Verification:
- Idea Used: DSS-based signatures for merchant onboarding.
- How: When a merchant registers on Khalti, they submit documents signed with a DSS key. Khalti’s system verifies the signature before approving the account.
NTC Electricity Bill Payments:
- Idea Used: RSA signatures for bill authenticity.
- How: NTC’s online portal signs bills with its private key. Customers verify the signature using NTC’s public key before paying.
Weaknesses and Mitigations
| Threat | Impact | Mitigation Strategy |
|---|---|---|
| Private Key Compromise | Forged signatures | Use Hardware Security Modules (HSMs) |
| Timestamping Server Fraud | Fake timestamps | Use multiple TSAs (e.g., GlobalSign + DigiCert) |
| Replay Attacks | Resending old signatures | Include nonce (unique transaction ID) |
| Hash Collisions | Tampered data appears valid | Use SHA-256/SHA-3 (collision-resistant) |
| Revoked Certificates | Stale public keys | Check Certificate Revocation Lists (CRLs) |
Legal Framework in Nepal
Nepal’s Electronic Transactions Act, 2063 (2008) recognizes digital signatures as legally valid under these conditions:
- The signature is unique to the signer.
- The signer maintains exclusive control over their private key.
- The signature is capable of identifying the signer.
- The signature is as reliable as a handwritten signature for the intended purpose.
Key Provisions:
- Section 5(2): Digital signatures are admissible in court if verified using the signer’s public key.
- Section 11: A third-party Certificate Authority (CA) must issue digital certificates (e.g., Nepal Government CA, ntc.gov.np).
Step-by-Step: Creating a Digital Signature (RSA Example)
Let’s trace how a Daraz seller signs an invoice for a customer in Kathmandu.
Invoice Details:
Order ID: DARAZ-NP-2024-056789 Seller: "TechGadgets Nepal" Buyer: "John Doe" Amount: NPR 12,500 Date: 2024-05-20Hashing:
- Compute
SHA-256("Order ID: DARAZ-NP-2024-056789 | ... | Date: 2024-05-20"). - Output:
a3f5b7...(64-character hex string).
- Compute
Signing with Private Key:
- The seller’s system encrypts the hash with their private key (e.g.,
RSA-2048). - Output:
Digital Signature = {a3f5b7...}_privateKey.
- The seller’s system encrypts the hash with their private key (e.g.,
Sending to Buyer:
- The invoice + signature is sent to John Doe via email/Daraz app.
Verification by Buyer:
- John Doe’s system:
- Computes the same SHA-256 hash of the invoice.
- Decrypts the signature using the seller’s public key (downloaded from Daraz’s CA).
- Compares the two hashes.
- If they match: Signature is valid.
- John Doe’s system:
Exam Tip: How to Score Full Marks
Define Clearly:
- Start with precise definitions:
- "A digital signature is a cryptographic technique that binds a user’s identity to a document using asymmetric encryption, ensuring authenticity, integrity, and non-repudiation."
- For non-repudiation: "Non-repudiation is the assurance that a party cannot deny the validity of their digital signature or action, enforced via timestamps and third-party validation."
- Start with precise definitions:
Compare DSS and RSA:
- Use a table (as shown above) and highlight one key difference in your answer (e.g., "DSS uses DSA for faster signing, while RSA relies on modular exponentiation").
Worked Examples:
- Always tie to Nepal:
- Use eSewa, NEPSE, or KMC fines in examples.
- Show step-by-step signing/verification (like the Daraz invoice above).
- Include timestamps if the question asks about non-repudiation.
- Always tie to Nepal:
Legal Angle:
- Mention Nepal’s Electronic Transactions Act, 2063 when discussing validity.
- Note that CAs (Certificate Authorities) are required for legal recognition.
Diagrams:
- Draw flowcharts for processes (e.g., signing/verification steps).
- Use tables for comparisons (DSS vs. RSA).
- Label real systems (e.g., eSewa’s signature flow).
Common Pitfalls to Avoid:
- ❌ Saying digital signatures are "unbreakable" (mention key compromise risks).
- ❌ Confusing hashing with encryption (emphasize that hashes are one-way).
- ❌ Ignoring timestamps in non-repudiation questions.
Pro Tip: For numerical questions (e.g., "Explain how RSA creates a digital signature"), describe the mathematical steps:
- Hash the message →
H = SHA-256(M). - Encrypt
Hwith the private key →S = H^d mod n(wheredis the private exponent). - Verify by decrypting
Swith the public key →H' = S^e mod n(whereeis the public exponent). - Check if
H == H'.
Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 13.
Discussion
Loading…